exam questions

Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Exam SC-200 topic 3 question 69 discussion

Actual exam question from Microsoft's SC-200
Question #: 69
Topic #: 3
[All SC-200 Questions]

HOTSPOT
-

You have a Microsoft Sentinel workspace.

A Microsoft Sentinel incident is generated as shown in the following exhibit.



Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

NOTE: Each correct selection is worth one point.

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
antoniokt
Highly Voted 2 years, 1 month ago
Investigate Comment
upvoted 7 times
...
user636
Most Recent 8 months ago
The correct answers are: - Investigate - Comments
upvoted 2 times
...
Ramye
1 year, 2 months ago
First box Investigation - clear choice Second box - two viable options Alerts or Comments. It's Comments per the below verbatim in this Microsoft article: https://learn.microsoft.com/en-us/azure/sentinel/investigate-incidents#audit-and-comment-on-incidents Audit and comment on incidents When investigating an incident, you'll want to thoroughly document the steps you take, both to ensure accurate reporting to management and to enable seamless cooperation and collaboration amongst coworkers. You'll also want to clearly see records of any actions taken on the incident by others, including by automated processes. Microsoft Sentinel gives you the Activity log, a rich audit and commenting environment, to help you accomplish this.
upvoted 3 times
...
chepeerick
1 year, 6 months ago
Correct option
upvoted 1 times
...
danb67
1 year, 6 months ago
You dont need to click investigate to see the entities. You can just highlight a sentinel incident and click entities. You can also get thesde by clicking invetigate then entities. Question out of date now maybe? 2nd comments for me. Poeple keep saying alerts but where within alerts does it show the steps one has taken to investigate the issue? Which is the ask. At the bottom of the setninel incident page there is comments section where you can add a comment. Anyone else working that incident can see the comment.
upvoted 3 times
luisM14
1 year, 1 month ago
Pay attention to "Map" detail. On entities, yes you can check entities, but with a map is only possible on Investigate
upvoted 2 times
...
Ramye
1 year, 2 months ago
At the end of the day, what are your answers?
upvoted 1 times
...
...
chepeerick
1 year, 6 months ago
Investigate and comments
upvoted 1 times
...
donathon
1 year, 7 months ago
Investigate and comments
upvoted 3 times
...
billo79152718
1 year, 8 months ago
Investigate Comments
upvoted 3 times
...
itsadel
1 year, 9 months ago
Investigation + Bookmark, Alerts are notifications that are generated when suspicious or malicious activity is detected. They can be used to notify you of potential threats, and they can also be used to start investigations. However, alerts do not provide a list of the activities that have been performed during an investigation. Comments are used to add notes to investigations. They can be used to track the progress of an investigation, or to provide additional information about the investigation. However, comments do not provide a list of the activities that have been performed during an investigation.
upvoted 1 times
JoeP1
1 year, 9 months ago
The last line of your comment says the second answer can not be Bookmarks.
upvoted 1 times
...
...
teouba
2 years ago
In order to check the activities during the investigation, normally you go to "Activity Log" and there you can check the activities and the comments. Since there is no "Activy Log" option, i would go for "Comments" Also from the below link we can see "Comment on incidents https://learn.microsoft.com/en-us/azure/sentinel/investigate-incidents#audit-and-comment-on-incidents As a security operations analyst, when investigating an incident you will want to thoroughly document the steps you take, both to ensure accurate reporting to management and to enable seamless cooperation and collaboration amongst coworkers. Microsoft Sentinel gives you a rich commenting environment to help you accomplish this." "Alerts" tab for sure doesnt show you the activities that took place during the investigation
upvoted 3 times
...
gg7648
2 years, 1 month ago
tested on Sentinel. its definitely, Investigate and Alerts.
upvoted 2 times
...
wyindualizer
2 years, 1 month ago
https://learn.microsoft.com/en-us/azure/sentinel/investigate-cases#comment-on-incidents the second one will be Comments
upvoted 2 times
...
Walaakb
2 years, 1 month ago
I don't think its alerts , I'm going with comments
upvoted 3 times
...
wsrudmen
2 years, 1 month ago
Investigate Alerts https://learn.microsoft.com/en-us/azure/sentinel/investigate-cases
upvoted 4 times
...
PhoenixSlasher
2 years, 2 months ago
Investigate <> Alerts Comments is only what has been added by a user nothing more.
upvoted 2 times
danb67
1 year, 8 months ago
Where within alerts does it show the steps one has taken to investigate the issue?
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago